| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
1 parent becbdcf commit e457c9a
7 files changed
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -35,12 +35,16 @@ | |||
| 35 | 35 | <version>${version.exec.maven}</version> | |
| 36 | 36 | <executions> | |
| 37 | 37 | <execution> | |
| 38 | - <phase>compile</phase> | ||
| 38 | + <phase>validate</phase> | ||
| 39 | 39 | <goals> | |
| 40 | 40 | <goal>java</goal> | |
| 41 | 41 | </goals> | |
| 42 | 42 | <configuration> | |
| 43 | 43 | <mainClass>org.owasp.benchmark.tools.BenchmarkCrawler</mainClass> | |
| 44 | + <arguments> | ||
| 45 | + <argument>${addlArg1}</argument> <!-- -f here --> | ||
| 46 | + <argument>${addlArg2}</argument> <!-- filename here --> | ||
| 47 | + </arguments> | ||
| 44 | 48 | </configuration> | |
| 45 | 49 | </execution> | |
| 46 | 50 | </executions> | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -1 +1,2 @@ | |||
| 1 | - call mvn compile -Pcrawler | ||
| 1 | + CALL mvn validate -Pcrawler | ||
| 2 | + | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -1,3 +1,3 @@ | |||
| 1 | 1 | #!/bin/sh | |
| 2 | - mvn compile -Pcrawler | ||
| 2 | + mvn validate -Pcrawler | ||
| 3 | 3 | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -1,2 +1,2 @@ | |||
| 1 | - sourceanalyzer -b benchmark -Xmx6G -scan -f benchmark.fpr | ||
| 1 | + sourceanalyzer -b benchmark -Xmx10G -scan -f benchmark.fpr | ||
| 2 | 2 | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -159,10 +159,19 @@ private void parseContrastJavaFinding(TestSuiteResults tr, String json) throws E | |||
| 159 | 159 | String uri = request.getString("uri"); | |
| 160 | 160 | ||
| 161 | 161 | if (tcr.getCWE() != 0 && uri.contains(BenchmarkScore.TESTCASENAME)) { | |
| 162 | - String testNumber = | ||
| 162 | + // Normal uri's look like: "uri":"/benchmark/cmdi-00/BenchmarkTest00215", but for | ||
| 163 | + // web services, they can look like: | ||
| 164 | + // "uri":"/benchmark/rest/xxe-00/BenchmarkTest03915/send" | ||
| 165 | + String testNumberStr = | ||
| 163 | 166 | uri.substring( | |
| 164 | - uri.lastIndexOf('/') + BenchmarkScore.TESTCASENAME.length() + 1); | ||
| 165 | - tcr.setNumber(Integer.parseInt(testNumber)); | ||
| 167 | + uri.indexOf(BenchmarkScore.TESTCASENAME) | ||
| 168 | + + BenchmarkScore.TESTCASENAME.length()); | ||
| 169 | + // At this point testNumber could contain '00215', or '03915/send' | ||
| 170 | + int slashIndex = testNumberStr.indexOf('/'); | ||
| 171 | + if (slashIndex > 0) { | ||
| 172 | + testNumberStr = testNumberStr.substring(0, slashIndex); | ||
| 173 | + } | ||
| 174 | + tcr.setNumber(Integer.parseInt(testNumberStr)); | ||
| 166 | 175 | // System.out.println( tcr.getNumber() + "\t" + tcr.getCWE() + "\t" + | |
| 167 | 176 | // tcr.getCategory() ); | |
| 168 | 177 | tr.put(tcr); | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -161,6 +161,9 @@ private static TestCaseResult parseFortifyVulnerability(Node vuln) { | |||
| 161 | 161 | private static int cweLookup(String vtype, String subtype, Node unifiedNode) { | |
| 162 | 162 | ||
| 163 | 163 | switch (vtype) { | |
| 164 | + case "Access Control": | ||
| 165 | + return 284; | ||
| 166 | + | ||
| 164 | 167 | case "Command Injection": | |
| 165 | 168 | return 78; | |
| 166 | 169 | ||
@@ -189,6 +192,8 @@ private static int cweLookup(String vtype, String subtype, Node unifiedNode) { | |||
| 189 | 192 | return 00; | |
| 190 | 193 | case "Denial of Service": | |
| 191 | 194 | return 400; | |
| 195 | + case "Dynamic Code Evaluation": | ||
| 196 | + return 95; | ||
| 192 | 197 | case "Header Manipulation": | |
| 193 | 198 | return 113; | |
| 194 | 199 | case "Hidden Field": | |
@@ -205,6 +210,7 @@ private static int cweLookup(String vtype, String subtype, Node unifiedNode) { | |||
| 205 | 210 | return 915; | |
| 206 | 211 | ||
| 207 | 212 | case "Missing Check against Null": | |
| 213 | + case "Missing Check for Null Parameter": | ||
| 208 | 214 | return 476; | |
| 209 | 215 | ||
| 210 | 216 | case "Missing XML Validation": | |
@@ -303,6 +309,7 @@ private static int cweLookup(String vtype, String subtype, Node unifiedNode) { | |||
| 303 | 309 | case "Hardcoded Domain in HTML": | |
| 304 | 310 | case "J2EE Bad Practices": | |
| 305 | 311 | case "J2EE Misconfiguration": | |
| 312 | + case "Object Model Violation": | ||
| 306 | 313 | case "Poor Style": | |
| 307 | 314 | case "Portability Flaw": | |
| 308 | 315 | case "Race Condition": | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -182,27 +182,29 @@ protected ResponseInfo sendRequest( | |||
| 182 | 182 | private static File processCommandLineArgs(String[] args) { | |
| 183 | 183 | ||
| 184 | 184 | String crawlerFileName = Utils.DATA_DIR + "benchmark-crawler-http.xml"; // default location | |
| 185 | - File crawlerFile = null; | ||
| 185 | + File crawlerFile = new File(crawlerFileName); // default location; | ||
| 186 | 186 | ||
| 187 | 187 | if (args == null || args.length == 0) { | |
| 188 | 188 | // No arguments is OK | |
| 189 | - crawlerFile = new File(crawlerFileName); // default location | ||
| 190 | 189 | } else if (args.length != 0 && args.length != 2) { | |
| 191 | 190 | System.out.println("Usage: no arguments or -f /PATH/TO/TESTSUITE-crawler-http.xml"); | |
| 191 | + return null; | ||
| 192 | 192 | } else if (args.length == 2) { | |
| 193 | 193 | if ("-f".equalsIgnoreCase(args[0])) { | |
| 194 | 194 | // -f indicates use the specified crawler file | |
| 195 | 195 | crawlerFileName = args[1]; | |
| 196 | 196 | crawlerFile = new File(crawlerFileName); | |
| 197 | 197 | } else if (!(args[0] == null | |
| 198 | 198 | && args[1] == null)) { // pom settings for crawler forces creation of 2 args, | |
| 199 | - // but if none are provided, they are null | ||
| 200 | 199 | System.out.println("Supported options: -f /PATH/TO/TESTSUITE-crawler-http.xml"); | |
| 200 | + return null; | ||
| 201 | 201 | } | |
| 202 | 202 | } | |
| 203 | - if (crawlerFile != null && !crawlerFile.exists()) { | ||
| 203 | + if (!crawlerFile.exists()) { | ||
| 204 | 204 | System.out.println( | |
| 205 | - "ERROR: Crawler Configuration file: '" + crawlerFileName + "' not found!"); | ||
| 205 | + "ERROR: Crawler Configuration file: '" | ||
| 206 | + + crawlerFile.getAbsolutePath() | ||
| 207 | + + "' not found!"); | ||
| 206 | 208 | crawlerFile = null; | |
| 207 | 209 | } | |
| 208 | 210 | ||
| Back | FazBrowse Home | New Git URL |
0 commit comments